Skip to content
Conference

TrustTwin: World-Model-Enhanced Twins for Trustworthy AIoT Decision Making

Aug 2026 · 2026 IEEE/CIC International Conference on Communications in China (ICCC) · pp. 271-276 · 0 citations · 14 references

Abstract

Recent advances in large language models are pushing IoT systems toward autonomous Artificial Intelligence of Things (AIoT) paradigms, where system behavior depends on protocol semantics, internal state, interaction history, and environmental context. This creates a gap between AI-generated decisions and the behavior of physical entities: a message may be protocol-valid yet unsafe in the current state. We present TrustTwin, a framework for trustworthy decision making based on specification-guided world models and executable twin validation. TrustTwin extracts device actions, states, preconditions, postconditions, and constraints from protocol specifications to evaluate candidate AI actions under the current context. It then validates predicted outcomes against an executable twin and triggers adaptive recovery when discrepancies occur, including revising, delaying, rejecting actions, or updating the model. We instantiate TrustTwin in the Matter ecosystem and show that it improves decision quality, reduces contextually inappropriate actions, and provides traceable feedback for adaptive control.

View source

Similar papers

Open access Sep 2026

Trust inversion and its exploitation: A threat model of the Model Context Protocol for agentic AI

The Model Context Protocol (MCP) standardizes connections between large language model applications and external tools and data. Its capability negotiation, dynamic discovery, insertion of tool results into model context, and server-initiated sampling create composition risks when server-originated artefacts influence...

M. Q. Sambo, Augustine Yusuf, I. Nwokoro et al. · 0 citations
Open access Sep 2026

Security Architecture for Agentic AI in Enterprise Cloud Environments: A Zero-Trust Framework for Secure Autonomous Systems

Agentic artificial intelligence expands the enterprise security boundary because autonomous agents can plan tasks, retain memory, invoke tools, call APIs, and initiate business actions. Authentication at session start is therefore insufficient when later actions may be influenced by untrusted content, poisoned memory,...

S. Suryawanshi · 0 citations
#artificial intelligence Review Sep 2026

Trustworthy Agentic AI: Failure Modes, Mitigation Strategies, and a Lifecycle Framework for Autonomous LLM Systems

Agentic AI systems built on large language models can plan over multiple steps, use external tools, retain information in memory, and coordinate with other agents. These capabilities make them more useful than static language models, but they also introduce new security and operational risks. Untrusted content from web...

Fayeq Jeelani Syed, Rehan Ahmad, Ali Al Bataineh et al. · 0 citations
Open access Sep 2026

Revocable Delegated Authority for Agentic AI in Hybrid Cloud Environments

Agentic AI systems act in hybrid cloud environments through federated identity and control-plane APIs, where an action can be technically authorized yet exceed the authority under which an agent should act. This study introduces Authority to Autonomously Act (AAA): a model of delegated autonomy as a continuously re-eva...

Paul Son, Yan-Zhen Qu · 0 citations
Preprint Aug 2026

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance

Charting these challenges provides a roadmap toward trustworthy autonomous agent deployment: security must become a verifiable property of the architectures, protocols, and runtimes that govern agent behavior, rather than an optional layer of guidance.

Alireza Lotfi, Subangkar Karmaker Shanto, Imtiaz Karim et al. · 2 citations
#artificial intelligence Preprint Sep 2026

ZeroGate: Trust-Preserving Fast Paths for Governed AI Agent Runtimes

Moving authorization earlier can shorten an agent's dispatch boundary without removing authorization work. It can also admit an action whose payload, authority, or relevant state has changed. ZeroGate separates exact-action approval from durable local admission: an issuer signs a short-lived ActionPass, and a trusted r...

Ze-Xu Wang · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.